CVE-2017-2623
CVE-2017-2623
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
27 jul 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Productos afectados
Project Atomic · rpm-ostree,¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →